Infinite loop in Linux kernel - CVE-2026-80820

 

Infinite loop in Linux kernel - CVE-2026-80820

Published: September 5, 2026


Vulnerability identifier: #VU147102
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80820
CWE-ID: CWE-835
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of circular linked lists in the XFS scrub unlinked inode list traversal when online filesystem checking processes an unlinked inode list containing a loop. A local user can cause online filesystem checking to traverse the circular list to cause a denial of service.


Affected software

Linux kernel

How to mitigate CVE-2026-80820

Install security update from vendor's repository.


External References

Related Security Bulletins